Distribute Rego policies through Artifact Hub? #583
Replies: 3 comments 1 reply
-
Good point! We have #533 but it's not mature enough to be an actionable issue, so this can be a good place to discuss. Definitely policies should be distributed out of band from the Tracee release lifecycle, and hosted and versioned outside of the release assets. |
Beta Was this translation helpful? Give feedback.
-
Yes, Artifact Hub as a distribution channel makes sense for Rego based policies. However, I wonder if we have now two ways of distribution and if we really do need both. They being the following:
I outline some pros & cons of the first approach here #533 (comment) |
Beta Was this translation helpful? Give feedback.
-
more options to the mix: another option is using an generic OCI registry. OPA/Conftest supports distributing rego file this way already. I'm actually surprised now that ArtifactHub isn't OCI as well. we'll need to run some comparison and determine the best option for us |
Beta Was this translation helpful? Give feedback.
-
Would it make sense for users to be able to obtain Tracee policies in Rego from Artifact Hub?
Beta Was this translation helpful? Give feedback.
All reactions